Gitlab News Articles

Recent news articles refferecing the vendors vulnerabilities.

(TLP CLEAR) Weekly Vulnerabilities to Prioritize – September 17, 2026 - WaterISAC

The below vulnerabilities have been identified by WaterISAC analysts as important for water and wastewater utilities to prioritize in their vulnerability management efforts. WaterISAC shares critical...

2 weeks ago

CISA Warns of Active Exploitation of Critical GitLab Flaw

CISA warns attackers are exploiting a critical GitLab flaw that exposes server files, credentials and development pipelines. Learn how to respond.

2 weeks ago

GitLab's Perfect-Score Flaw Exposes Servers to Unauthenticated File Theft as CISA Sounds Alarm

CISA added CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab, to its KEV catalog after confirmed exploitation. The bug lets unauthenticated attackers read arbitrary files via the commits API. Self-managed users must patch versions before 19.1.8, 19.2.6, and 19.3.2 immediately.

2 weeks ago

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

2 weeks ago

CISA: Hackers now exploit max severity GitLab flaw in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks.

2 weeks ago

GitLab's Worst-Rated Vulnerability Is Already Being Exploited - IT Security News

GitLab on September 10 shipped emergency patches for a maximum-severity vulnerability that lets unauthenticated attackers read arbitrary files off a server and by the following morning, attackers were already...

2 weeks ago

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks - IT Security News

2026-09-12 07:09 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities...

3 weeks ago

CISA Warns of GitLab Path Traversal Vulnerability Exploited in Attacks

CISA has added a critical GitLab vulnerability, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting the flaw.

3 weeks ago

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab patched CVE-2026-85706, a CVSS 10 path traversal flaw enabling unauthenticated file reads, as in-the-wild probes began.

3 weeks ago

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825.

3 weeks ago

GitLab Vulnerability Exploited One Day After Disclosure

Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public disclosure.

3 weeks ago

Critical GitLab Code Injection Vulnerability Actively Exploited in Attacks

GitLab admins are urged to patch CVE-2026-19478 as attackers exploit the critical unauthenticated code injection flaw.I prefer this response

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - SwapUpdate

Ravie LakshmananAug 21, 2026Vulnerability / Enterprise Security

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure

GitLab CVE-2026-19478 is under active exploitation, with unauthenticated attacks able to modify or delete public projects under certain conditions.

GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure - NewsBreak

A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in

Critical GitLab Flaw Exploited Shortly After Disclosure

Hackers started exploiting CVE-2026-19478, a critical, unauthenticated GitLab vulnerability, shortly after public disclosure.

GitLab Patches Critical CVE-2026-19478 GraphQL Vulnerability  | eSecurity Planet

GitLab patched a critical GraphQL flaw as researchers observed exploitation attempts.

GitLab's Out-of-Band Patch Exposes Lingering GraphQL Risks in Self-Managed DevOps Pipelines

GitLab issued an emergency patch on August 17, 2026 for CVE-2026-19478, a critical GraphQL code injection flaw (CVSS 9.4) allowing unauthenticated attackers to modify or delete public projects under certain conditions. Self-managed instances from version 18.2 onward require immediate upgrades to 19....

Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478.

GitLab Emergency Patch: Third GraphQL Flaw of 2026 Lets Unauthenticated Attackers Delete Projects

GitLab vulnerability CVE-2026-19478 carries a CVSS 9.4 rating, letting unauthenticated attackers remotely delete or modify public projects with no login required. An emergency patch released August

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478) - Help Net Security

GitLab has patched a critical, unauthenticated code injection flaw (CVE-2026-19478) that let attackers delete public projects and user data.

GitLab Patches Critical Code Injection Vulnerability

GitLab has patched CVE-2026-19478, a critical code injection vulnerability that can be exploited without authentication.

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab patches CVE-2026-19478, a CVSS 9.4 GraphQL flaw that could let unauthenticated attackers modify or delete public project and user data

CVE-2025-6948 | GitLab Community Edition/Enterprise Edition up to 17.11.5/18.0.3/18.1.1 cross site scripting (Issue 552616)

A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 17.11.5/18.0.3/18.1.1 and classified as problematic. Affected by this vulnerability is an unknown functional…

No more news articles to load.